w3c / w3c/securityig

Work Item: AI in the Browser Threat Model

Open
#20 5 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
9
Forks
4
PR merge metrics
No merged PRs in 30d

Description

Following the CfC, thanks to @tomcjones we have a Threat Model for AI in the Browser.

We have AI in different scenarios:

  • Web API (i.e., Writing Assistance API)
  • Browser Level (i.e., Extension)
  • Using Agent (i.e., Operator)
  • Agentic Web (i.e., via protocols)

The first scenario was already detailed by Tom here.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read the linked CfC and Tom Jones's existing “AI in a Scripted User Agent” threat model first. Use the four scenarios listed in the issue to determine the remaining threat-model coverage, with completion marked by a documented threat model for AI in the Browser.

Written by the indexing model from the issue text.

Assessment

Domain
ai, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.